Probably brute force protection, since not every account has 2FA enabled. I can understand it, but I agree it is really annoying.
But it shows even for 2FA enabled accounts. Change that stupidity to require recaptcha
OR 2FA at step 2.
But before logging in there is no way to know whether the account you are about to login with has 2FA enabled right?